# Cluster status: red

**URL:** <https://discuss.elastic.co/t/cluster-status-red/12854>\
**Category:** Elasticsearch\
**Created:** [July 18, 2013, 11:37pm UTC](https://discuss.elastic.co/t/cluster-status-red/12854 "2013-07-18T23:37:31Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Barry\_Morrison](https://avatars.discourse-cdn.com/v4/letter/b/3bc359/32.png) [@Barry\_Morrison](https://discuss.elastic.co/u/Barry_Morrison)\
**Post date:** [July 18, 2013, 11:37pm UTC](https://discuss.elastic.co/t/cluster-status-red/12854/1 "2013-07-18T23:37:31Z")

</div>

Using Elasticsearch for Logstash. Everything was working. Came back after  
lunch, no results.

Started digging further, found this:

curl -XGET '[http://127.0.0.1:9200/\_cluster/health?pretty=true](http://127.0.0.1:9200/_cluster/health?pretty=true)'  
{  
"cluster\_name" : "elasticsearch",  
"status" : "red",  
"timed\_out" : false,  
"number\_of\_nodes" : 2,  
"number\_of\_data\_nodes" : 1,  
"active\_primary\_shards" : 0,  
"active\_shards" : 0,  
"relocating\_shards" : 0,  
"initializing\_shards" : 4,  
"unassigned\_shards" : 76  
}

Various threads have shown me, this is bad.

Best that I can tell from the logs, this is when it happened  
[https://gist.github.com/esacteksab/6033983](https://gist.github.com/esacteksab/6033983)

Anyway to get those unassigned\_shards back?

Logstash/Elasticsearch exist on the same server, "defaults" otherwise.  
Everything has been working for over a week...until a few hours ago.

Thanks,  
Barry

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![cthoma](https://avatars.discourse-cdn.com/v4/letter/c/b487fb/32.png) [@cthoma](https://discuss.elastic.co/u/cthoma)\
**Post date:** [July 18, 2013, 11:57pm UTC](https://discuss.elastic.co/t/cluster-status-red/12854/2 "2013-07-18T23:57:32Z")

</div>

Are you using different es versions in one cluster? Could this cause an error?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Barry\_Morrison](https://avatars.discourse-cdn.com/v4/letter/b/3bc359/32.png) [@Barry\_Morrison](https://discuss.elastic.co/u/Barry_Morrison)\
**Post date:** [July 19, 2013, 12:00am UTC](https://discuss.elastic.co/t/cluster-status-red/12854/3 "2013-07-19T00:00:58Z")

</div>

Originally I stood up on 0.90.2. And had this problem. It was then  
mentioned to go to 0.20.6. Problem still exists, regardless of the version.

I am now still on 0.20.6.

On Thu, Jul 18, 2013 at 4:57 PM, cthoma [thch0014@gmail.com](mailto:thch0014@gmail.com) wrote:

> Are you using different es versions in one cluster? Could this cause an  
> error?
> 
> --  
> You received this message because you are subscribed to a topic in the  
> Google Groups "elasticsearch" group.  
> To unsubscribe from this topic, visit  
> [https://groups.google.com/d/topic/elasticsearch/vnjNZRsdxhY/unsubscribe](https://groups.google.com/d/topic/elasticsearch/vnjNZRsdxhY/unsubscribe).  
> To unsubscribe from this group and all its topics, send an email to  
> [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Barry\_Morrison](https://avatars.discourse-cdn.com/v4/letter/b/3bc359/32.png) [@Barry\_Morrison](https://discuss.elastic.co/u/Barry_Morrison)\
**Post date:** [July 19, 2013, 12:05am UTC](https://discuss.elastic.co/t/cluster-status-red/12854/4 "2013-07-19T00:05:38Z")

</div>

More information for the sake of information:

curl -XGET '[http://127.0.0.1:9200/\_cluster/nodes/\_local?pretty=true](http://127.0.0.1:9200/_cluster/nodes/_local?pretty=true)'  
{  
"ok" : true,  
"cluster\_name" : "elasticsearch",  
"nodes" : {  
"3Vne3-D2Q-S0Fu8Q4aMpmA" : {  
"name" : "Kate Neville",  
"transport\_address" :  
"inet[ip-10-245-10-23.us-west-2.compute.internal/10.245.10.23:9300]",  
"hostname" : "[logger00.mine.net](http://logger00.mine.net)",  
"version" : "0.20.6",  
"http\_address" : "inet[/10.245.10.23:9200]"  
}  
}  
}

On Thursday, July 18, 2013 4:37:31 PM UTC-7, Barry Morrison wrote:

> Using Elasticsearch for Logstash. Everything was working. Came back after  
> lunch, no results.
> 
> Started digging further, found this:
> 
> curl -XGET '[http://127.0.0.1:9200/\_cluster/health?pretty=true](http://127.0.0.1:9200/_cluster/health?pretty=true)'  
> {  
> "cluster\_name" : "elasticsearch",  
> "status" : "red",  
> "timed\_out" : false,  
> "number\_of\_nodes" : 2,  
> "number\_of\_data\_nodes" : 1,  
> "active\_primary\_shards" : 0,  
> "active\_shards" : 0,  
> "relocating\_shards" : 0,  
> "initializing\_shards" : 4,  
> "unassigned\_shards" : 76  
> }
> 
> Various threads have shown me, this is bad.
> 
> Best that I can tell from the logs, this is when it happened  
> [https://gist.github.com/esacteksab/6033983](https://gist.github.com/esacteksab/6033983)
> 
> Anyway to get those unassigned\_shards back?
> 
> Logstash/Elasticsearch exist on the same server, "defaults" otherwise.  
> Everything has been working for over a week...until a few hours ago.
> 
> Thanks,  
> Barry

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 19, 2013, 6:32am UTC](https://discuss.elastic.co/t/cluster-status-red/12854/5 "2013-07-19T06:32:48Z")

</div>

Hey,

minor question: did you try to use the same data files after downgrading  
from 0.90 to 0.20? (they might not be compatible in that direction)

--Alex

On Fri, Jul 19, 2013 at 2:05 AM, Barry Morrison [barry@versal.com](mailto:barry@versal.com) wrote:

> More information for the sake of information:
> 
> curl -XGET '[http://127.0.0.1:9200/\_cluster/nodes/\_local?pretty=true](http://127.0.0.1:9200/_cluster/nodes/_local?pretty=true)'  
> {  
> "ok" : true,  
> "cluster\_name" : "elasticsearch",  
> "nodes" : {  
> "3Vne3-D2Q-S0Fu8Q4aMpmA" : {  
> "name" : "Kate Neville",  
> "transport\_address" :  
> "inet[ip-10-245-10-23.us-west-2.compute.internal/10.245.10.23:9300]",  
> "hostname" : "[logger00.mine.net](http://logger00.mine.net)",  
> "version" : "0.20.6",  
> "http\_address" : "inet[/10.245.10.23:9200]"  
> }  
> }  
> }
> 
> On Thursday, July 18, 2013 4:37:31 PM UTC-7, Barry Morrison wrote:
> 
> > Using Elasticsearch for Logstash. Everything was working. Came back after  
> > lunch, no results.
> > 
> > Started digging further, found this:
> > 
> > curl -XGET '[http://127.0.0.1:9200/\_\*\*cluster/health?pretty=true](http://127.0.0.1:9200/_**cluster/health?pretty=true)[http://127.0.0.1:9200/\_cluster/health?pretty=true](http://127.0.0.1:9200/_cluster/health?pretty=true)  
> > '  
> > {  
> > "cluster\_name" : "elasticsearch",  
> > "status" : "red",  
> > "timed\_out" : false,  
> > "number\_of\_nodes" : 2,  
> > "number\_of\_data\_nodes" : 1,  
> > "active\_primary\_shards" : 0,  
> > "active\_shards" : 0,  
> > "relocating\_shards" : 0,  
> > "initializing\_shards" : 4,  
> > "unassigned\_shards" : 76  
> > }
> > 
> > Various threads have shown me, this is bad.
> > 
> > Best that I can tell from the logs, this is when it happened  
> > [https://gist.github](https://gist.github).\*\*com/esacteksab/6033983[https://gist.github.com/esacteksab/6033983](https://gist.github.com/esacteksab/6033983)
> > 
> > Anyway to get those unassigned\_shards back?
> > 
> > Logstash/Elasticsearch exist on the same server, "defaults" otherwise.  
> > Everything has been working for over a week...until a few hours ago.
> > 
> > Thanks,  
> > Barry
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Barry\_Morrison](https://avatars.discourse-cdn.com/v4/letter/b/3bc359/32.png) [@Barry\_Morrison](https://discuss.elastic.co/u/Barry_Morrison)\
**Post date:** [July 19, 2013, 3:37pm UTC](https://discuss.elastic.co/t/cluster-status-red/12854/6 "2013-07-19T15:37:31Z")

</div>

Alex,  
The problem started/existed with 0.90.2.

Logstash folks recommended 0.20.6. Problem still exists.

So while the data may be incompatible, it is still broken, regardless of  
the version.

On Thu, Jul 18, 2013 at 11:32 PM, Alexander Reelsen [alr@spinscale.de](mailto:alr@spinscale.de)wrote:

> Hey,
> 
> minor question: did you try to use the same data files after downgrading  
> from 0.90 to 0.20? (they might not be compatible in that direction)
> 
> --Alex
> 
> On Fri, Jul 19, 2013 at 2:05 AM, Barry Morrison [barry@versal.com](mailto:barry@versal.com) wrote:
> 
> > More information for the sake of information:
> > 
> > curl -XGET '[http://127.0.0.1:9200/\_cluster/nodes/\_local?pretty=true](http://127.0.0.1:9200/_cluster/nodes/_local?pretty=true)'  
> > {  
> > "ok" : true,  
> > "cluster\_name" : "elasticsearch",  
> > "nodes" : {  
> > "3Vne3-D2Q-S0Fu8Q4aMpmA" : {  
> > "name" : "Kate Neville",  
> > "transport\_address" :  
> > "inet[ip-10-245-10-23.us-west-2.compute.internal/10.245.10.23:9300]",  
> > "hostname" : "[logger00.mine.net](http://logger00.mine.net)",  
> > "version" : "0.20.6",  
> > "http\_address" : "inet[/10.245.10.23:9200]"  
> > }  
> > }  
> > }
> > 
> > On Thursday, July 18, 2013 4:37:31 PM UTC-7, Barry Morrison wrote:
> > 
> > > Using Elasticsearch for Logstash. Everything was working. Came back  
> > > after lunch, no results.
> > > 
> > > Started digging further, found this:
> > > 
> > > curl -XGET '[http://127.0.0.1:9200/\_\*\*cluster/health?pretty=true](http://127.0.0.1:9200/_**cluster/health?pretty=true)[http://127.0.0.1:9200/\_cluster/health?pretty=true](http://127.0.0.1:9200/_cluster/health?pretty=true)  
> > > '  
> > > {  
> > > "cluster\_name" : "elasticsearch",  
> > > "status" : "red",  
> > > "timed\_out" : false,  
> > > "number\_of\_nodes" : 2,  
> > > "number\_of\_data\_nodes" : 1,  
> > > "active\_primary\_shards" : 0,  
> > > "active\_shards" : 0,  
> > > "relocating\_shards" : 0,  
> > > "initializing\_shards" : 4,  
> > > "unassigned\_shards" : 76  
> > > }
> > > 
> > > Various threads have shown me, this is bad.
> > > 
> > > Best that I can tell from the logs, this is when it happened  
> > > [https://gist.github](https://gist.github).\*\*com/esacteksab/6033983[https://gist.github.com/esacteksab/6033983](https://gist.github.com/esacteksab/6033983)
> > > 
> > > Anyway to get those unassigned\_shards back?
> > > 
> > > Logstash/Elasticsearch exist on the same server, "defaults" otherwise.  
> > > Everything has been working for over a week...until a few hours ago.
> > > 
> > > Thanks,  
> > > Barry
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to a topic in the  
> Google Groups "elasticsearch" group.  
> To unsubscribe from this topic, visit  
> [https://groups.google.com/d/topic/elasticsearch/vnjNZRsdxhY/unsubscribe](https://groups.google.com/d/topic/elasticsearch/vnjNZRsdxhY/unsubscribe).  
> To unsubscribe from this group and all its topics, send an email to  
> [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:25am UTC](https://discuss.elastic.co/t/cluster-status-red/12854/7 "2017-07-06T02:25:26Z")

</div>


